SME Squeeze: NIS2, AI Act, Ransomware Collide

On January 7, 2026, the ransomware group Akira hit Buhlmann Group, a Hamburg-based steel and metal trading company with roughly 2,000 employees and €428 million in annual revenue. The attackers made off with about 55GB of data — engineering drawings, HR files, financial records — before anyone at the company could respond. Buhlmann wasn’t an isolated case; it was one of five incidents that, according to securitytoday.de, defined Germany’s first quarter of 2026 — a quarter in which roughly 80% of ransomware victims were small and mid-sized businesses. It’s an early sign of the SME squeeze now closing in from multiple directions at once — regulatory and criminal pressure landing on the same under-resourced teams.

That attack landed in the middle of a stretch when German SMEs were supposed to be working through two compliance deadlines at once. The first — registration under the country’s new NIS2 law — has technically lapsed twice now. The second, a narrower but still binding obligation under the EU AI Act, arrived on August 2. Neither deadline slows down an attacker like Akira. For a one- or two-person security team inside a 150-employee company, all three clocks are now running at the same time. That’s the SME squeeze in miniature.

Germany's NIS2 registration grace period adds to the SME squeeze for thousands of companies

Only about 11,500 of the roughly 29,500 companies covered by NIS2 had registered by the March 6 deadline — a gap that pushed the BSI to extend a grace period through July 31, 2026.

The Compliance Clock: NIS2’s Grace Period Just Expired

Germany’s NIS2 implementation law (NIS2UmsuCG) took effect on December 6, 2025 — about 14 months after the original EU transposition deadline, a delay that triggered an infringement procedure from the European Commission. The law expanded German cybersecurity regulation from roughly 4,500 critical-infrastructure operators to about 29,500 companies across 18 sectors, including manufacturing, logistics, food production, and digital infrastructure — many of which had never been subject to sector-specific security regulation before.

Companies had to self-assess and register with the BSI (Germany’s federal cybersecurity agency) within three months, by March 6, 2026. By that date, only about 11,500 of the estimated 29,500 affected companies had actually registered — a gap wide enough that the BSI granted a grace period through July 31, 2026. Registrations did pick up in the following months, climbing to roughly 15,500 by early April and just under 18,500 by the end of May, but even that pace wasn’t enough to close the gap before the grace period ran out. That deadline has now passed too, without anywhere near the attention the original one received.

The obligations tied to registration aren’t a formality. Companies classified as “essential entities” (250+ employees or €50M+ revenue) face fines of up to €10 million or 2% of global annual revenue for risk-management or reporting failures; “important entities” (50+ employees or €10M+ revenue) face up to €7 million or 1.4%. Late registration alone can draw a fine of up to €500,000 under Section 65 BSIG, and management is personally liable under Section 38 BSIG for failing to implement required measures. Reporting timelines are just as tight: an initial notification within 24 hours of a significant incident, a deeper assessment within 72 hours, and a final report within one month.

For companies that have missed both deadlines, waiting for a third one isn’t an option. A late registration still beats no registration, and the law’s seven core obligations — risk analysis, incident response, business continuity, supply-chain security, secure procurement and development, effectiveness measurement, and staff training — need to exist regardless of where a company sits in the registration queue. NIS2 doesn’t mandate a specific certification, but ISO 27001 is explicitly recognized as evidence of the required “state of the art” — making it the fastest credible route to demonstrating compliance, rather than building a framework from scratch.

A narrower EU AI Act transparency obligation took effect on August 2, 2026

The AI Act’s Annex III high-risk obligations were pushed to December 2027, but the narrower Article 50 transparency rule still took effect on schedule, August 2, 2026.

A Narrower, but Still Real, AI Act Obligation Adds to the SME Squeeze

August 2, 2026 was originally supposed to be a much bigger date for the EU AI Act — the point at which high-risk AI systems under Annex III (think hiring, creditworthiness assessment, or education) would need full technical documentation, risk management, CE marking, and registration in the EU database. That deadline has since moved. Under the EU’s “Digital Omnibus” agreement — now formally in force as Regulation (EU) 2026/1744, published in the Official Journal on July 24, 2026 and effective July 27 — Annex III obligations shift to December 2, 2027, and Annex I obligations (AI embedded in regulated products like machinery or vehicles) move to August 2, 2028.

What didn’t move is Article 50 — the Digital Omnibus changed nothing about this date; it was always the scheduled deadline for this narrower obligation. Its transparency requirements — that chatbots, deepfakes, and emotion-recognition or biometric-categorization systems clearly disclose that a user is interacting with AI — took effect exactly as planned on August 2, 2026. One narrower transition period does exist: machine-readable marking for AI systems already on the market before August 2, 2026 doesn’t have to comply until December 2, 2026. For an SME, all of this is a much smaller lift than full high-risk compliance, but it isn’t nothing: any customer-facing chatbot, AI-generated marketing content, or automated decision tool now has to identify itself as AI-powered — a governance and documentation question that lands squarely on top of already-active NIS2 work.

The lesson isn’t “the AI Act crisis was called off.” It’s that regulatory deadlines rarely move as a single package — parts of a law can slip while other parts proceed exactly on schedule, and a compliance program built around one headline date can miss the part that’s actually enforceable today.

Cyber extortion attacks are accelerating the SME squeeze faster than compliance timelines can keep up

Cyber-extortion victims in Germany rose 91% year-over-year, according to Orange Cyberdefense’s Security Navigator 2026, with SMEs disproportionately affected.

None of This Is Slowing Attackers Down

While the compliance clocks were running, the actual threat kept accelerating. The number of known cyber-extortion victims in Germany rose 91% year-over-year, according to Orange Cyberdefense’s Security Navigator 2026, which analyzed more than 139,000 security incidents between October 2024 and September 2025 — with small and mid-sized companies of up to 250 employees disproportionately affected.

Bitkom’s “Wirtschaftsschutz 2025” study puts a scale on it: 87% of German companies were attacked in the past twelve months, up from 81% the year before, with total damage to the German economy reaching €289.2 billion. Ransomware was the most common attack method, hitting 34% of affected firms, ahead of DDoS attacks (25%), malware infections (24%), phishing (22%), and password attacks (21%). Check Point separately recorded a 124% year-over-year increase in attacks across Germany, Austria, and Switzerland in 2025.

The Buhlmann case fits this pattern exactly: an established, mid-market industrial company — not a bank, not critical infrastructure in the traditional sense — holding exactly the kind of operational and financial data that makes extortion profitable. Companies in that position are simultaneously the most likely to be targeted and the least likely to have an in-house security team to fall back on.

What the SME Squeeze Means for a Stretched Security Team

Three clocks, one team — the SME squeeze in practice. A few practical priorities for SMEs trying to keep pace with all three at once:

  • Check your NIS2 registration status now, even though both deadlines have passed. The self-assessment obligation doesn’t disappear because a registration window closed, and a late registration is rated far better than no registration at all.
  • Treat ISO 27001 alignment as a practical shortcut to NIS2’s “state of the art” requirement, not a separate, competing compliance project. The seven control areas NIS2 requires overlap heavily with what ISO 27001 already documents.
  • Check whether any customer-facing AI tool — chatbot, content generator, automated screening tool — currently discloses that it’s AI. Article 50’s obligations are narrower than the headline AI Act deadline, which makes them easy to miss entirely.
  • Plan on the assumption that an extortion attempt will happen, not just that it could. With extortion victims up 91% year-over-year, continuous detection and a tested response plan matter just as much as the paper that documents they exist.

Cybersecurity buyer’s remorse aside, the companies that handle the SME squeeze well aren’t the ones treating NIS2, the AI Act, and ransomware readiness as three separate projects. They’re the ones building a single security and governance foundation that answers all three questions at once.

A small IT and compliance team reviewing security and regulatory status together

Meeting NIS2, the AI Act, and ransomware readiness at once takes one coordinated security program, not three separate projects.

This is exactly where DIESEC’s services come in: our NIS2 and Governance, Risk and Compliance offering helps SMEs turn NIS2 and AI Act obligations into a structured, ISO-27001-aligned program instead of a scramble after a missed deadline. Because paper alone doesn’t stop an attack like Akira’s, our SOC as a Service provides the continuous monitoring that catches an extortion attempt before 55GB of data walks out the door, and our penetration testing verifies that the protections on paper hold up in practice before an attacker tests them for you.

Contact us today to find out where your compliance status and your defenses actually stand.